Helix is a financially motivated data-extortion brand and threat cluster associated with identity-centric intrusions against enterprise cloud environments, especially Microsoft 365 and SharePoint. Reporting links Helix to the broader UNC6671 ecosystem, which has also operated under the BlackFile, Redact, Pink, and Falcon names. Multiple researchers assess strong tradecraft and infrastructure overlap among these brands, although some relationships remain framed as possible splintering, affiliate activity, or shared phishing-as-a-service support rather than conclusively unified attribution. Helix operations emphasize social engineering over software exploitation. The group is known for voice phishing that impersonates IT help desk staff, coworkers, managers, or executives, often contacting employees on personal mobile devices and creating urgency around security migrations, passkey enrollment, or account issues. Helix has used adversary-in-the-middle phishing and device code phishing to capture credentials, MFA tokens, or authenticated cloud sessions. After access is obtained, operators commonly register attacker-controlled MFA authenticators to maintain persistence and may abuse password resets and mailbox access to suppress alerts and retain control. Post-compromise activity is centered on cloud data theft and extortion. Helix targets SaaS and identity platforms including Microsoft 365, Okta, SharePoint, and related enterprise services. Observed behavior includes reconnaissance of SharePoint content, automated enumeration, bulk collection, and scripted exfiltration using Python and PowerShell tooling. The group has also been observed deleting password-reset confirmations, security notifications, phishing-awareness messages, and MFA-change alerts for defense evasion. In some cases, Helix moved from initial access to mass data theft in under an hour. Helix is primarily associated with data-theft extortion rather than encryption-led ransomware deployment. Victim pressure mechanisms include ransom demands, negotiation, threats to publish stolen information, leak-site style exposure, and phased release workflows in which stolen SharePoint data is staged into tiers with countdown-based publication. Reported targeting spans financial services, private equity, professional services, legal organizations, technology, transportation, hospitality, insurance, healthcare, manufacturing, and real estate, with a notable focus on organizations holding sensitive corporate data such as mergers and acquisitions, litigation, investor, and client records. Publicly reported victims attributed to the Helix brand include organizations in the United States and Canada. Helix has also been discussed as a possible offshoot or successor within the BlackFile and ShinyHunters-adjacent ecosystem because of overlapping social-engineering methods, infrastructure patterns, and cloud-focused extortion tradecraft. Those links are suggestive but not conclusively established. The dominant, well-supported characterization is that Helix is a fast-moving, malware-light, identity-abuse-driven extortion operation focused on stealing high-value enterprise data from cloud collaboration environments and monetizing it through extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of four successor brands/groups that UNC6671/BlackFile reportedly split into, continuing the same vishing and extortion tradecraft.
Public extortion brand linked to UNC6671 and referenced in shared phishing-domain usage across victims.
Conducting a ransomware attack against Westland Insurance.
Conducting a ransomware attack and associated extortion against Morguard, including negotiation pressure, deadlines, and threatened publication of data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.